PT-2017-6688 · Canonical · Usb-Creator
Tavis Ormandy
·
Publicado
2015-04-23
·
Atualizado
2017-10-11
·
CVE-2015-3643
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
usb-creator versions prior to 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS
usb-creator versions prior to 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS
usb-creator versions prior to 0.2.62ubuntu0.3 on Ubuntu 14.10
usb-creator versions prior to 0.2.67ubuntu0.1 on Ubuntu 15.04
Description
The issue allows local users to gain privileges by leveraging a missing call to
check polkit for the KVMTest method.Recommendations
For usb-creator version prior to 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, update to version 0.2.38.3ubuntu0.1 or later.
For usb-creator version prior to 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, update to version 0.2.56.3ubuntu0.1 or later.
For usb-creator version prior to 0.2.62ubuntu0.3 on Ubuntu 14.10, update to version 0.2.62ubuntu0.3 or later.
For usb-creator version prior to 0.2.67ubuntu0.1 on Ubuntu 15.04, update to version 0.2.67ubuntu0.1 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Usb-Creator